{"id":10481,"date":"2019-07-17T00:21:00","date_gmt":"2019-07-16T22:21:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=10481"},"modified":"2021-12-17T18:36:46","modified_gmt":"2021-12-17T17:36:46","slug":"windows-10-important-secure-boot-bitlocker-bug-fix","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2019\/07\/17\/windows-10-important-secure-boot-bitlocker-bug-fix\/","title":{"rendered":"Windows 10: Important Secure Boot\/Bitlocker Bug-Fix"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"http:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/win102.jpg\" width=\"58\" height=\"58\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2019\/07\/12\/windows-10-wichtiger-secure-boot-bitlocker-bug-fix\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]Today a short note for Windows 10 users who use Bitlocker with Secure Boot. And Microsoft has released an important Servicing Stack Update (SSU) for all supported Windows 10 versions, which is supposed to solve a Bitlocker problem in connection with Secure Boot.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg05.met.vgwort.de\/na\/05bf4ab8c6a5450a877247a9b19b9b71\" alt=\"\" width=\"1\" height=\"1\" \/>Preliminary note: Users with Windows 10 Home are not affected by the following instructions.<\/p>\n<h2>Secure Boot affects Bitlocker<\/h2>\n<p>UEFI and Secure Boot are always good for trouble. For Microsoft's Surface devices, for example, the problem is known that Bitlocker goes into recovery mode and requires a recovery key when an update to the UEFI or TPM firmware is installed.<\/p>\n<p>In general, however, there is a bug in the secure boot of UEFI systems that causes an activated bitlocker to be forced into recovery mode at system startup. Microsoft now tackles this problem with a Servicing Stack Update (SSU).Generell gibt es aber wohl im Secure Boot von UEFI-Systemen einen Bug, der dazu f\u00fchrt, dass ein aktiviertes Bitlocker beim Systemstart in den Recovery-Mode gezwungen wird. Genau dieses Problem packt Microsoft nun mit einem Servicing Stack Update (SSU) an.<\/p>\n<h2>Update KB4509096 for Windows 10 V1903<\/h2>\n<p>On July 9, 2019, Microsoft released the Servicing Stack Update (SSU) <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4509096\/windows-10-update-kb4509096\" target=\"_blank\" rel=\"noopener noreferrer\">KB4509096<\/a> for Windows 10 Version 1903 as part of the regular patchday. As usual, Microsoft promises quality improvements in the Servicing Stack so that Windows updates can be installed more easily afterwards. This time, however, the SSU KB4509096 contains important information. Microsoft points out an important fix in the Key-Changes:<\/p>\n<blockquote><p>Addresses an issue with a Secure Boot feature update that may cause BitLocker to go into recovery mode because of a race condition.<\/p><\/blockquote>\n<p>This update addresses an issue related to a secure boot feature update. A race condition occurs when starting a system with Secure Boot enabled. I interpret it to mean that it can cause the Bitlocker module to become active before the Secure Boot checks are complete. As a result, Bitlocker is forced into recovery mode, in which a recovery key is queried.<\/p>\n<p>The update is automatically distributed via Windows Update, but is also available via <a href=\"https:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=KB4509096\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Update Catalog<\/a>. A restart is not required after installing the SSU and there are no installation requirements.<\/p>\n<h2>Updates for Windows 10 V1507 to V1809<\/h2>\n<p>If you browse the list of Servicing Stack updates under <a href=\"https:\/\/web.archive.org\/web\/20201101085445\/https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/ADV990001\" target=\"_blank\" rel=\"noopener noreferrer\">ADV990001<\/a> and call up the corresponding KB articles, they all contain the reference to the Bitlocker fix. Here is the list of relevant updates<\/p>\n<ul>\n<li><a href=\"https:\/\/support.microsoft.com\/help\/4509095\" target=\"_blank\" rel=\"noopener noreferrer\">KB4509095<\/a>: Windows 10 Version 1809<\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/help\/4509094\" target=\"_blank\" rel=\"noopener noreferrer\">KB4509094<\/a>: Windows 10 Version 1803<\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/help\/4509093\" target=\"_blank\" rel=\"noopener noreferrer\">KB4509093<\/a>: Windows 10 Version 1709<\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/help\/4509092\" target=\"_blank\" rel=\"noopener noreferrer\">KB4509092<\/a>: Windows 10 Version 1703<\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/help\/4509091\" target=\"_blank\" rel=\"noopener noreferrer\">KB4509091<\/a>: Windows 10 Version 1607<\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/help\/4509090\" target=\"_blank\" rel=\"noopener noreferrer\">KB4509090<\/a>: Windows 10 Version (RTM)<\/li>\n<\/ul>\n<p>The updates are provided via Windows Update and may be downloaded from <a href=\"https:\/\/www.catalog.update.microsoft.com\/Home.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Update Catalog<\/a>.<\/p>\n<h2>Microsoft and the SSU Recommendation<\/h2>\n<p>Microsoft strongly recommends that you install the latest Service Stack Update (SSU) on Windows 10 V1903 before installing the latest Cumulative Update (LCU). By installing Service Stack Updates (SSU), users ensure, according to Microsoft, that they have a robust and reliable service stack so that their devices can receive and install Microsoft security fixes.<\/p>\n<blockquote><p>You can find some information where a Servicing Stack Update is running around (namely in the Windows PE phase when restarting during the Windows Update installation) in <a href=\"https:\/\/www.tenforums.com\/windows-10-news\/136263-new-kb4509096-servicing-stack-update-windows-10-v1903-july-9-a.html#post1670539\" target=\"_blank\" rel=\"noopener noreferrer\">this forum post<\/a>.<\/p><\/blockquote>\n<p>Microsoft actually recommends this for all updates and writes in its KB articles that the required SSUs are automatically taken into account when installing via Windows Update. But Redmond doesn't get it right with Windows 10 &#8211; I remember my blog post <a href=\"https:\/\/borncity.com\/win\/2019\/06\/20\/windows-10-ssu-problem-in-sccm-uservoice-thematisiert\/\">Windows 10: SSU issue addressed in SCCM UserVoice<\/a>. Administrators who manage updates using software tools such as WSUS or SCCM should ensure that the KB4509096 update is installed in any case.<\/p>\n<blockquote><p>At this point a little hint (thanks to Jan Sch\u00fcssler from heise for the hint). The SSU KB4509096 does not appear in the list of installed updates in Windows Update (i.e. the update process, see picture above). If you go to \"Uninstall Updates\" in the classic Control Panel, the SSU is listed.<\/p><\/blockquote>\n<p><strong>Article series:\u00a0<\/strong><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2019\/07\/17\/windows-10-important-secure-boot-bitlocker-bug-fix\/\">Windows 10: Important Secure Boot\/Bitlocker Bug-Fix<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/?p=10522\">Windows 10: Bitlocker encrypts automatically<\/a><\/p>\n<p><strong>Similar articles<\/strong><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2019\/05\/09\/bitlocker-management-in-enterprise-environments\/\">BitLocker management in enterprise environments<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2018\/10\/30\/dell-new-bios-is-causing-bitlocker-issues\/\">Dell: New BIOS is causing Bitlocker issues<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2018\/11\/07\/bitlocker-on-ssds-microsoft-security-advisory-notification-nov-6-2018\/\">Bitlocker on SSDs: Microsoft Security Advisory Notification (Nov. 6, 2018)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2018\/11\/06\/ssd-vulnerability-breaks-bitlocker-encryption\/\">SSD vulnerability breaks (Bitlocker) encryption<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2018\/09\/20\/windows-10-v1803-fix-for-bitlocker-bug-in-nov-2018\/\">Windows 10 V1803: Fix for Bitlocker bug in Nov. 2018?<\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Today a short note for Windows 10 users who use Bitlocker with Secure Boot. And Microsoft has released an important Servicing Stack Update (SSU) for all supported Windows 10 versions, which is supposed to solve a Bitlocker problem in connection &hellip; <a href=\"https:\/\/borncity.com\/win\/2019\/07\/17\/windows-10-important-secure-boot-bitlocker-bug-fix\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[463,2],"tags":[356,47,76],"class_list":["post-10481","post","type-post","status-publish","format-standard","hentry","category-issue","category-windows","tag-bitlocker","tag-issue","tag-windows-10"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/10481","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=10481"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/10481\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=10481"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=10481"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=10481"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}